AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14332

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress prior to version 7.0.9 is vulnerable due to a lack of capability checks and nonce verification on store-management actions. This flaw allows any authenticated user, including subscribers, to disconnect the store, effectively taking the storefront offline until an administrator intervenes. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-14332
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
WordPress

Original NVD Description

The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its store-management actions, allowing any authenticated user, such as a subscriber, to disconnect the store and take the storefront offline until an administrator reconnects it.